Junglewise Threat Intelligence

CVE-2026-49198: Acer Connect W6x improper access control in MQTT broker

CVE-2026-49198 · Severity: info · CVSS 8.3 · Published 2026-05-29

Technologies: Acer Connect W6x Router. Vendors: Acer.

Executive brief

The Acer Connect W6x router contains a security flaw in its internal messaging system (MQTT) used for device communication. An attacker with basic network access can subscribe to all message traffic using 'wildcard' requests, allowing them to intercept sensitive data or monitor device activity. This could lead to the exposure of private information transmitted between the router and connected applications.

Technical details

An improper access control vulnerability (CWE-284) exists in the local MQTT broker of Acer Connect W6x routers. The broker fails to properly enforce Access Control Lists (ACLs) regarding wildcard topic subscriptions. A remote attacker with low-level authenticated access can subscribe to '#' or similar wildcards to monitor all messages passing through the broker. This exposes sensitive system or user data transmitted via the MQTT protocol. The issue is resolved in firmware version W6x_GBL_2.00.000008.

Affected products

  • Acer Connect W6x Router W6x_GBL_2.00.000005 and earlier

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory
  • 2026-05-29: patched: Fixed in firmware W6x_GBL_2.00.000008

References

Related threats